Vulnerabilities
Vulnerable Software
Esri:  >> Arcgis Enterprise  >> 10.9  Security Vulnerabilities
There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes, which under unique circumstances could allow a remote, authenticated attacker with low‑privileged access to compromise the confidentiality, integrity, and availability of the software. Successful exploitation allows the attacker to cross an authentication and authorization boundary beyond their originally assigned access, resulting in a scope change.
CVSS Score
8.5
EPSS Score
0.016
Published
2024-04-04
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.
CVSS Score
5.3
EPSS Score
0.013
Published
2021-12-07


Contact Us

Shodan ® - All rights reserved